Impact
Keploy versions 3.1.0 through 3.6.25 bind the agent control-plane HTTP server to all interfaces without authentication, exposing endpoints that stream TLS session keys and traffic data. Attackers can access the /agent/pcap/keylog endpoint to retrieve NSS keylog lines and decrypt recorded TLS traffic, or invoke the /agent/stop and /agent/storemocks endpoints to manipulate recording sessions. This results in a breach of confidentiality and potential manipulation of the agent’s operation.
Affected Systems
Keploy agent versions from 3.1.0 through 3.6.25 are affected. The issue stems from the agent control-plane server binding to all network interfaces without enforcing authentication, exposing sensitive endpoints.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity vulnerability. EPSS score is < 1%, indicating a very low exploitation probability, yet the lack of authentication and exposure of all interfaces make exploitation straightforward for anyone who can reach the agent. The vulnerability is not listed in CISA KEV, but its impact is significant due to the ability to decrypt TLS traffic and alter agent behavior.
OpenCVE Enrichment